A new cyber threat, the MedusaHVNC Trojan, has been identified, allowing cybercriminals to covertly access and control a victim’s computer through an invisible virtual desktop. This malware utilizes the victim’s browser data, including cookies and logged-in sessions, without alerting the user.
Malware-as-a-Service: MedusaHVNC
MedusaHVNC is marketed as a service, making it accessible for criminals via a dedicated website and Telegram. This advancement in hidden VNC technology, traditionally used in banking scams, now offers a ready-to-use package for illicit activities.
Researchers from BlackFog have revealed that this Trojan creates a separate Windows desktop environment, enabling attackers to operate without detection. Users remain unaware as their screens appear normal while unauthorized activities occur in the background.
Exploiting Trusted Devices
The MedusaHVNC Trojan exploits the victim’s real browser profile on the infected device, making unauthorized activities appear legitimate. This method helps bypass fraud detection systems that rely on location and device authenticity, posing a significant threat to banking and online services.
Additional features of MedusaHVNC include executing .NET and native payloads in memory, bypassing security measures like AMSI and ETW, and extracting sensitive information such as passwords and browsing history from major browsers and applications.
Complex Infection Process
The infection process of MedusaHVNC is complex and involves multiple stages. It begins with a JScript launcher that sets up the malware components and ensures persistence through system reboots. The payload is cleverly injected into legitimate Windows processes to avoid detection.
Encryption techniques like XOR and ChaCha20 are used to conceal the final payload, which communicates with a command-and-control server. Once active, the malware leverages Windows APIs to manage the hidden desktop, facilitating unauthorized access and control.
Security experts have noted that MedusaHVNC’s design aligns with broader trends in malware development, emphasizing the use of legitimate tools to minimize detection while ensuring ongoing access to compromised systems.
Detecting MedusaHVNC Activity
Security teams are advised to monitor for unusual activities such as unexpected processes under legitimate Windows applications, peculiar script executions, and unusual network connections. These signs can indicate the presence of MedusaHVNC even when it evades traditional signature-based detection.
Enhancing threat detection capabilities is crucial for combating sophisticated threats like MedusaHVNC. Integrating robust security measures and continuous monitoring can help identify and mitigate these stealthy cyber threats effectively.
